Skip to content
Discussion options

You must be logged in to vote

Snyk is right - axios does not prevent SSRF automatically. You need to validate URLs before passing them in.

Here's a solid baseline validator for backend file download scenarios:

import { URL } from 'url'

// private/loopback ranges that shouldn't be reachable
const PRIVATE_IP = /^(127\.|10\.|192\.168\.|172\.(1[6-9]|2\d|3[01])\.|::1|localhost)/i

function assertSafeUrl(rawUrl: string): void {
  let parsed: URL
  try {
    parsed = new URL(rawUrl)
  } catch {
    throw new Error(`Invalid URL: ${rawUrl}`)
  }

  if (!['http:', 'https:'].includes(parsed.protocol)) {
    throw new Error(`Disallowed protocol: ${parsed.protocol}`)
  }

  if (PRIVATE_IP.test(parsed.hostname)) {
    throw new Error

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@bakugo
Comment options

Answer selected by Mael-Abgrall
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants